Spoofhound

Set up single sign-on

Let your people sign in to Spoofhound with your organisation’s own login instead of a Spoofhound password. Spoofhound speaks OpenID Connect, which every major identity provider supports.

Microsoft Entra ID

Step by step, from creating the groups to your first sign-in.

Read the steps →

Google Directory · Okta

Planned. Single sign-on with Google Directory and Okta is on the way; Microsoft Entra ID is the supported provider today. Ask us if you need Google or Okta and we will talk about timing.

What is the same whoever you use

You prove the domain first

Before anything else, you publish a TXT record proving you control the domain your people sign in with. Spoofhound will not route a domain’s logins anywhere until that record is in place. Without it, anyone could type your domain into their own account and capture your staff’s sign-ins.

This is a different record from the one that verifies a domain for reporting. That one proves we may send you a domain’s DMARC reports. This one proves you may decide who signs in as its people, which is a much stronger claim — so it gets its own proof. It also means the domain your staff log in with does not have to be a domain you monitor, and those are often not the same domain.

Three groups decide what people can do

You create three groups in your directory and tell Spoofhound each one’s id. Somebody’s role is read from your login token every single time they sign in, so moving them between groups changes what they can do, and it corrects itself without anyone telling us.

Suggested groupWhat that person can do
SpoofhoundAdmins Everything, including domains, members, invitations, AI keys and settings.
SpoofhoundAnalysers Everything a viewer can do, plus running an analysis and working through an action plan — the things that spend your AI budget.
SpoofhoundViewers Reads everything. Changes nothing.

Call them whatever your own naming standard says — we never see the names, only each group’s id. The names above are a suggestion for anyone starting from nothing, in one word because a group name ends up inside scripts and exports that all disagree about spaces and punctuation.

Somebody in more than one group gets the highest of them. Somebody in none of them cannot sign in — which is how you remove access: take them out of the groups.

Nothing switches on until you have signed in once

Saving the settings changes nothing. Enforcement — passwords and passkeys off, your identity provider the only way in — starts by itself the first time an admin completes a sign-in through it. One wrong value would otherwise lock out everybody including whoever typed it, and it has to be an admin because that is what proves the admin group is mapped correctly and somebody can still run the account afterwards.

Anybody with no account in your directory at all — a contractor, or somebody at another company — can be named as an exception and keeps their password. Everyone excused is listed on the same screen, so you can always see who is not coming through your provider.

Getting back in when your provider breaks

You are given a recovery credential when you save the settings — before anything is switched on, while somebody is still looking at the screen. Long, random, and shown once. Put it in a password manager. Pasting it at our recovery page turns enforcement off so passwords and passkeys work again, and that page needs no sign-in, which is the whole point of it.

It does not log anybody in. Whoever uses it still has to authenticate — that is what stops it being a master key to your account. It works once, every use is written to your audit log, and every admin on the account is emailed the moment it happens.

Separately, you are asked for a sign-in problem contact address — who we contact if single sign-on breaks, or if somebody is guessing at your recovery credential. It is someone to contact, not a way in: nothing sent there signs anybody in.

Use one at a different provider. If Entra ID is down, your Exchange Online mailbox is down too — which is exactly when we would need to write to you. It is required, and an address at a domain you have proved for single sign-on is refused.

People who have no account at your provider

Contractors, or somebody at another company you have invited to read reports. An admin can name them as exceptions, and each one is listed on the settings screen so it is always visible who is signing in without your identity provider.

One account, one instance

Spoofhound runs separate instances in different regions and accounts do not span them. If you have accounts on two instances, you configure single sign-on on each.

Stuck? Ask us — we would rather walk you through it than have you guess.